ISC CGRC Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Festlegung des Geltungsbereichs und des Kontexts | - Zuordnung behördlicher und rechtlicher Anforderungen - Bestimmung des organisatorischen Geltungsbereichs |
| Thema 2: Rahmenwerke für Kontrollmaßnahmen und deren Umsetzung | - Umsetzung und Prüfung von Kontrollmaßnahmen - Auswahl von Sicherheits- und Compliance-Kontrollen |
| Thema 3: Risikomanagement | - Erkennung und Bewertung von Risiken - Strategien zur Behandlung und Minderung von Risiken |
| Thema 4: Weiterentwicklung und Verbesserung des GRC-Programms | - Verfahren zur kontinuierlichen Verbesserung - Kennzahlen und Berichterstattung im Rahmen von GRC-Programmen |
| Thema 5: Management von Vorfällen und Ausnahmefällen | - Meldung und Eskalation von Vorfällen - Behandlung von Abweichungen von Vorschriften |
| Thema 6: Überwachung und fortlaufende Einhaltung von Vorschriften | - Prüfungs- und Bestätigungsverfahren - Verfahren zur Überwachung der Compliance |
| Thema 7: Programm für Governance, Risikomanagement und Compliance | - Rollen und Verantwortlichkeiten der Beteiligten im Bereich GRC - GRC-Grundsätze und Entwicklung von Rahmenwerken |
ISC Certified in Governance Risk and Compliance CGRC Prüfungsfragen mit Lösungen
1. The authorization boundary of a system undergoing assessment comprises of:
Response:
A) Any components found withing the given Internet Protocol (IP) range
B) The information System (IS) elements to be authorized for operation as well as interconnected systems
C) The information System (IS) elements to be authorized for operation
D) Any elements or systems specified by the Chief Information Owner (CIO)
2. Security controls that can support multiple information systems efficiently and effectively as a common capability.
Their implementation results in a security capability that is inheritable by multiple information systems; such as Network boundary defense, management constraints, personnel security, security of physical structures, etc..
Response:
A) Security Controls
B) Common Controls
C) Common Controls Provider
D) Inherited Control
3. Which of the following roles is also known as the accreditor? Response:
A) Data owner
B) Designated Approving Authority
C) Chief Risk Officer
D) Chief Information Officer
4. When a Information System Owner applies a risk based approach to his selection of specific controls; this adjustment is called __________. The revised/tailored control baseline is documented in the system security plan.
Response:
A) Tailoring
B) Scoping
C) Failing
D) Passing
5. You are working as a project manager in your organization. You are nearing the final stages of project execution and looking towards the final risk monitoring and controlling activities. For your project archives, which one of the following is an output of risk monitoring and control? Response:
A) Qualitative risk analysis
B) Risk audits
C) Requested changes
D) Quantitative risk analysis
Fragen und Antworten:
| 1. Frage Antwort: C | 2. Frage Antwort: B | 3. Frage Antwort: B | 4. Frage Antwort: A | 5. Frage Antwort: C |






911 Kundenbewertungen

